Loading market data...

Term Finance Shuts Down Meta Vaults After Governance Exploit

Term Finance Shuts Down Meta Vaults After Governance Exploit

Term Finance permanently shut down its Meta Vaults after a governance exploit, halting new deposits while leaving withdrawals open. Term Labs revoked the vaults' DAO governance roles, and security researchers tracked the attacker's haul to roughly 2,843 ETH, $6.87 million, plus 1.68 million USDC that was swapped for DAI. The protocol hasn't confirmed the total or published its own vault-by-vault accounting.

The two transactions

The first transaction, at 06:25 UTC on Aug. 23, hit an ETH Meta Vault. A DeFiPrime reconstruction shows a proposal sat open for six days without a veto, and its first execution step set the delay cooldown to zero. That removed the second waiting period before routing 2,841.7435 WETH through a newly added strategy to an attacker-controlled address.

About 22 minutes later, a second transaction executed five proposals across five USDC vaults, pulling out 1,679,639.29 USDC. PeckShield put the combined loss near $8.5 million, though Term hasn't confirmed that figure.

How the bypass worked

Term's Meta Vaults ran on a governance opt-out system. LP token holders could veto queued parameter changes during a seven-day delay. If no veto came, the change became executable. The attacker's proposal apparently sailed through that window, then zeroed out the cooldown that should have forced a second waiting period before funds could move.

That's the part Term hasn't explained. The protocol hasn't published a postmortem detailing how the proposer got authority to queue those actions, or why the veto and delay controls didn't catch them.

What Term has said

Term says its underlying protocol and direct borrowing and lending markets were unaffected, based on its investigation so far. It's still verifying the scope of the breach. The team is working with outside security firms on remediation and recovery, but hasn't committed to reimbursing depositors or given a timetable.

Yearn's take

Yearn said the vault contracts use Yearn V3 architecture, but the exploit came through Term's custom governance wrapper. Standard Yearn vaults weren't touched, which narrows the blast radius.

For now, Meta Vaults are closed to new money, but withdrawals remain open. The open question is whether Term will cover the losses — and what, if anything, stops a similar governance attack elsewhere.